Description
GitPython 3.1.59 fails to restrict the --no-index option in the high-level diff API, allowing attackers to read arbitrary filesystem paths as repository operands. Attackers can combine --no-index with -I/--ignore-matching-lines to create a content-dependent Boolean oracle, repeatedly querying local files to recover single-line secrets through distinguishable success or error responses.
Published: 2026-09-09
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

Based on the description, the flaw resides in the high‑level diff API of GitPython 3.1.59, where the --no-index switch is not properly constrained. An attacker can invoke GitPython with this option to feed arbitrary file system paths as repository operands. By pairing --no-index with the -I/--ignore-matching-lines flag, the attacker turns the API into a content‑dependent Boolean oracle, repeatedly probing local files and distinguishing success from error responses. This indicates that the attacker must be able to execute the GitPython code locally on the target host. Using this capability, the attacker can recover single‑line secrets such as passwords, API keys, or other sensitive data found in the filesystem, presenting a clear confidentiality risk.

Affected Systems

Vendors: GitPython developers. Product: GitPython 3.1.59. The vulnerability is specific to this release and does not affect earlier or later versions that have applied the patch and removed the unchecked usage of --no-index.

Risk and Exploitability

Based on the description, the likely attack vector involves local execution of the vulnerable GitPython code on the target host. This local execution is needed to supply arbitrary filesystem paths via --no-index and probe file contents by exploiting the Boolean oracle. The CVSS score of 7.1 indicates high severity, and the lack of an EPSS score and KEV listing suggest no widespread exploitation yet. Attackers able to run the compromised code locally can repeatedly query local files, distinguishing success from error responses, potentially exfiltrating secrets if present on the system. Overall, despite the absence of remote entry, the combination of local execution and unchecked --no-index handling creates a significant confidentiality risk.

Generated by OpenCVE AI on September 10, 2026 at 02:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade GitPython to the latest supported release that removes the unchecked --no-index handling
  • Avoid using the --no-index option in any scripts or applications until the migration is applied
  • If immediate upgrade is not possible, sandbox GitPython execution to restrict filesystem access or ensure the process runs with minimal privileges to limit exposure

Generated by OpenCVE AI on September 10, 2026 at 02:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:gitpython_project:gitpython:*:*:*:*:*:python:*:*

Thu, 10 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Gitpython-developers
Gitpython-developers gitpython
Vendors & Products Gitpython-developers
Gitpython-developers gitpython

Thu, 10 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-73
References
Metrics threat_severity

None

threat_severity

Moderate


Wed, 09 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Description GitPython 3.1.59 fails to restrict the --no-index option in the high-level diff API, allowing attackers to read arbitrary filesystem paths as repository operands. Attackers can combine --no-index with -I/--ignore-matching-lines to create a content-dependent Boolean oracle, repeatedly querying local files to recover single-line secrets through distinguishable success or error responses.
Title GitPython 3.1.59 Local File Content Oracle via --no-index
First Time appeared Gitpython Project
Gitpython Project gitpython
Weaknesses CWE-88
CPEs cpe:2.3:a:gitpython_project:gitpython:*:*:*:*:*:*:*:*
Vendors & Products Gitpython Project
Gitpython Project gitpython
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Gitpython-developers Gitpython
Gitpython Project Gitpython
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-09T14:06:49.761Z

Reserved: 2026-09-09T10:32:34.109Z

Link: CVE-2026-87818

cve-icon Vulnrichment

Updated: 2026-09-09T14:06:46.202Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T12:17:16.980

Modified: 2026-09-16T15:12:45.633

Link: CVE-2026-87818

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-09T11:21:04Z

Links: CVE-2026-87818 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T10:15:17Z

Weaknesses
  • CWE-73

    External Control of File Name or Path

  • CWE-88

    Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')